Medical Taiwan 2026 Exhibition Review : Secure Vectors Surveillance Forms Alliance with Applus+ Laboratories Creates a One-Stop Compliance Channel for FDA and MDR Medical Device Information Security
/0 Comments/in EventsMedical Taiwan 2026 Event Recap
SVS Partners with Applus+ Laboratories
to Build a One-Stop FDA & MDR Cybersecurity Compliance Pathway for Medical Devices
Published: July 14, 2026 | Author: Secure Vectors Surveillance (SVS)
Medical Taiwan, Taiwan's premier international medical and healthcare exhibition, was held at Taipei World Trade Center Hall 1 from June 25 to 27, 2026, drawing medical device manufacturers, international buyers, and regulatory professionals from across the industry. At the exhibition, Secure Vectors Surveillance (SVS) and the Spanish testing and certification group Applus+ Laboratories formally introduced their strategic partnership — a single, streamlined pathway to cybersecurity compliance for Taiwanese medical device exporters pursuing both US FDA and EU MDR market access.
Drawing on three days of conversations at our booth, this article reviews the questions most frequently raised by Taiwanese medical device manufacturers, together with the practical guidance offered by the SVS and Applus+ Laboratories teams.
Josep Prat, China Managing Director, Applus+ Laboratories.
Highlight 1 | The Three Questions We Heard Most from Taiwanese Manufacturers
This year's exhibition brought together 316 exhibitors across more than 500 booths and welcomed over 7,600 trade visitors from Taiwan and abroad. Throughout the three-day event, our consultants spoke at length with industry professionals visiting our booth. Three questions surfaced repeatedly in these conversations — questions that go to the heart of how Taiwanese manufacturers are navigating today's shifting international regulatory landscape:
Question 1: How much time remains in the MDR transition period — and does it apply to my product?
A common misconception is that the 2027 and 2028 sunset deadlines apply universally. In fact:
- Only products that held a valid CE certificate under the former MDD/AIMDD directives before May 26, 2021 — so-called legacy devices — qualify for the extended transition period;
- Products developed after 2021 must proceed directly through the full MDR pathway, with no grace period of any kind.
Put simply, the transition extension preserves market access for existing products; it offers no buffer for new ones. A manufacturer launching a new connected medical device in 2026 must prepare its submission to MDR requirements from the outset.
Question 2: How demanding are the cybersecurity requirements under FDA Section 524B?
SVS Chief Executive Officer Vincent Huang illustrated the point with a case drawn from practice: a Bluetooth-enabled cardiac monitor that had previously cleared 510(k) review without difficulty was, upon resubmission to the FDA in 2024, required to furnish the following documentation:
- A complete SBOM (Software Bill of Materials), covering all third-party components and their versions;
- Threat model documentation clearly defining the boundaries of the attack surface;
- A penetration testing report spanning three interfaces: the mobile application, the cloud platform, and Bluetooth communications;
- A vulnerability management plan, including binding commitments on post-market remediation timelines.
Should any of these elements be missing, the FDA is empowered under Section 524B to issue a Refuse to Accept (RTA) determination — a statutory authority the agency has held since 2023. Manufacturers that defer cybersecurity testing until an RTA notice arrives typically face a 30-day remediation window, and where the deficiencies require changes to the underlying software architecture, the delay can cost them their market window altogether.
Question 3: What is Applus+ Laboratories' standing globally — and why has SVS chosen to partner with them?
This was, understandably, the most candid question we received. Applus+ Laboratories belongs to one of the world's leading testing, inspection, and certification groups, with 2024 group revenue of €2.2 billion, a workforce of more than 28,000, and operations in over 65 countries. Within the group are two EU MDR Notified Bodies:
- NB 2764, located in Turkey;
- NB 3121, located in Slovenia.
Taiwan has no EU MDR Notified Body of its own. This is by design: under the MDR framework, Notified Bodies must be established within the European Economic Area or in countries holding bilateral agreements with the EU. Through the local partnership with SVS, Taiwanese manufacturers gain a direct route to these European Notified Bodies — and can complete the MDR CE marking process through a single local point of contact, without seeking representation abroad.
Highlight 2 | "One Set of Evidence, Three Market Submissions" in Practice
At the heart of the partnership lies a simple principle: one set of evidence, three market submissions. Taiwanese manufacturers targeting the European, US, and Chinese markets have traditionally been required to prepare three separately formatted sets of cybersecurity documentation. Under the integrated process, a single set of technical documentation now serves all three regimes:
- EU MDR (Annex I §17, IEC 81001-5-1, and MDCG 2019-16);
- US FDA (Section 524B and UL 2900-2-1);
- China NMPA (YY/T 1843).
The value of this approach is particularly clear for Taiwanese ODM and OEM manufacturers. Producing each documentation set independently has historically taken three to six months, with duplicated consulting and testing fees frequently consuming more than 30% of a project's budget. Under the integrated process, a single SBOM, a single penetration testing report, and a single threat model support submissions across all three markets.
Highlight 3 | The Technical Documentation Matrix for Class III Devices
Another topic of considerable interest was the technical documentation matrix for Class IIa, IIb, and III software-driven medical devices. Consider a Class III connected device — an implantable defibrillator, for example, or an AI-enabled diagnostic instrument. The MDR does not mandate the use of any particular technical standard; in practice, however, the industry relies on a recognized set of standards and guidance documents to demonstrate conformity with the current State of the Art:
| Standard / Guidance | Scope |
|---|---|
| ISO 13485:2016 | Quality management systems |
| ISO 14971:2019 | Risk management, integrating cybersecurity and clinical risk |
| IEC 62304:2006+A1:2015 | Medical device software life cycle processes |
| IEC 81001-5-1:2021 | Cybersecurity life cycle for health software |
| MDCG 2019-16 | EU guidance on cybersecurity for medical devices |
These five documents have traditionally been prepared by separate teams, giving rise to what might be called documentation silos. Under the integrated consulting process offered by SVS and Applus+ Laboratories, all five are developed and aligned along a single project timeline — substantially reducing the risk that a Notified Body will return the submission for restructuring.
Next Steps After the Show
For manufacturers who visited the SVS booth during the exhibition, we recommend three immediate actions:
- Review your product classification and legacy device status to determine whether the MDR transition period applies to your portfolio;
- Schedule a complimentary 60-minute gap analysis, in which SVS consultants will assess your cybersecurity documentation against the IEC 81001-5-1 framework and identify any gaps;
- Register for our MDR cybersecurity workshop, commencing in July — a half-day, hands-on session covering SBOM generation, threat modeling, and penetration testing, with a certificate of training issued to all participants.
To arrange a consultation or register for the workshop, please complete the training interest form (course details will be announced in advance) or contact us at service@securevectors.com.
Related Coverage
- GBI Monthly (環球生技月刊) | EU MDR — Counting Down to 2027: SVS and Applus+ Laboratories Establish a One-Stop MDR and FDA Cybersecurity Compliance Pathway for Taiwan's Medical Device Industry
- iThome | CRA Countdown: SVS and Applus+ Laboratories Bring One-Stop EN 18031 and CRA Cybersecurity Testing and Compliance to Taiwan
- CIO Taiwan | SVS Partners with Applus+ Laboratories to Pursue Third-Party Testing and Certification Opportunities
Keywords: EU MDR, FDA Section 524B, FDA 510(k), MDR Annex I §17, IEC 81001-5-1, MDCG 2019-16, ISO 13485, ISO 14971, IEC 62304, ISO/IEC 17025, SBOM, threat modeling, penetration testing, connected medical device cybersecurity, Cyber Device, Applus+ Laboratories, NB 2764, NB 3121, Secure Vectors Surveillance, SVS, Secure Vectors, Medical Taiwan 2026






SVITI
SVITI
